Solved Desktop Adverts

Sorry #david, adaware installed stuff I did not want, changed my search engine and installed toolbars without my knowledge or acceptance. It also failed to find premiumoptions
 

My Computer

System One

  • OS
    Win 10
    Computer type
    PC/Desktop
    System Manufacturer/Model
    pc specialist made to order
    CPU
    Intel® Core™i7 Quad Core Processor i7-4790 (3.6GHz) 8MB Cache
    Motherboard
    ASUS® H81M-PLUS: Micro-ATX, LG1150, USB 3.0, SATA 6GBs
    Memory
    16GB KINGSTON DUAL-DDR3 1600MHz (2 x 8GB)
    Graphics Card(s)
    2GB NVIDIA GEFORCE GTX 750 Ti - DVI, mHDMI, VGA - 3D Vision Ready
    Sound Card
    ONBOARD 6 CHANNEL (5.1) HIGH DEF AUDIO (AS STANDARD)
    Monitor(s) Displays
    iiyama 24 inch flat screen
    Screen Resolution
    1920 x 1080
    Hard Drives
    1TB 3.5" SEAGATE SSHD, SATA 6Gb/s 7200 RPM (64MB + 8GB SSD CACHE)

    2TB Seagate SATA HDD

    500Gb SATA docked
    Case
    In Win Turbo
    Cooling
    Super Quiet 22dBA Triple Copper Heatpipe Intel CPU Cooler
    Keyboard
    microsoft mutlimedia keyboard
    Mouse
    logitech corded
    Internet Speed
    152mb
    Browser
    FF, IE11
    Antivirus
    AVG Internet Security 2015
    Other Info
    16x BLU-RAY WRITER DRIVE, 16x DVD ±R/±RW

    10/100/1000 GIGABIT LAN PORT
just been into iobit again, and start menu programs, services, found folder but cannot delete it but it is now disabled, I hope.

adaware did not find it
 

My Computer

System One

  • OS
    Win 10
    Computer type
    PC/Desktop
    System Manufacturer/Model
    pc specialist made to order
    CPU
    Intel® Core™i7 Quad Core Processor i7-4790 (3.6GHz) 8MB Cache
    Motherboard
    ASUS® H81M-PLUS: Micro-ATX, LG1150, USB 3.0, SATA 6GBs
    Memory
    16GB KINGSTON DUAL-DDR3 1600MHz (2 x 8GB)
    Graphics Card(s)
    2GB NVIDIA GEFORCE GTX 750 Ti - DVI, mHDMI, VGA - 3D Vision Ready
    Sound Card
    ONBOARD 6 CHANNEL (5.1) HIGH DEF AUDIO (AS STANDARD)
    Monitor(s) Displays
    iiyama 24 inch flat screen
    Screen Resolution
    1920 x 1080
    Hard Drives
    1TB 3.5" SEAGATE SSHD, SATA 6Gb/s 7200 RPM (64MB + 8GB SSD CACHE)

    2TB Seagate SATA HDD

    500Gb SATA docked
    Case
    In Win Turbo
    Cooling
    Super Quiet 22dBA Triple Copper Heatpipe Intel CPU Cooler
    Keyboard
    microsoft mutlimedia keyboard
    Mouse
    logitech corded
    Internet Speed
    152mb
    Browser
    FF, IE11
    Antivirus
    AVG Internet Security 2015
    Other Info
    16x BLU-RAY WRITER DRIVE, 16x DVD ±R/±RW

    10/100/1000 GIGABIT LAN PORT
Adaware, is a very lousy program, and it has become malware itself these last few years.

You have something in your system, which is loading up a list of spam sites, and telling IE to pop them up at random times.

Copy the link address from that spam link you posted, and do a search for it in Regedit. See if it comes up, it should be in a list of a bunch of similar spamsites. When/if you find it, delete the whole list.

I suppose the final thing you can do is run "Combofix" - But be very careful. Also, run "Hijackthis" and post the results, lest us see what it finds.

HiJackThis | Free software downloads at SourceForge.net
 

My Computer

System One

  • OS
    Windows 8 Pro with Media Center/Windows 7
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Asus M2N-MX SE Plus § DualCore AMD Athlon 64 X2, 2300 MHz (11.5 x 200) 4400+ § Corsair Value Select
    CPU
    AMD 4400+/4200+
    Motherboard
    Asus M2N-MX SE Plus/Asus A8M2N-LA (NodusM)
    Memory
    2 GB/3GB
    Graphics Card(s)
    GeForce 8400 GS/GeForce 210
    Sound Card
    nVIDIA GT218 - High Definition Audio Controller
    Monitor(s) Displays
    Hitachi 40" LCD HDTV
    Screen Resolution
    "1842 x 1036"
    Hard Drives
    WDC WD50 00AAKS-007AA SCSI Disk Device
    ST1000DL 002-9TT153 SCSI Disk Device
    WDC WD3200AAJB-00J3A0 ATA Device
    WDC WD32 WD-WCAPZ2942630 USB Device
    WD My Book 1140 USB Device
    PSU
    Works 550w
    Case
    MSI "M-Box"
    Cooling
    Water Cooled
    Keyboard
    Dell Keyboard
    Mouse
    Microsoft Intellimouse
    Internet Speed
    Cable Medium Speed
    Browser
    Chrome/IE 10
    Antivirus
    Eset NOD32 6.x/Win Defend
    Other Info
    Recently lost my Windows 8 on my main PC, had to go back to Windows 7.
I did have chrome as default until a few hours ago, the pc was really slow, so I did another scan and it found 22 malware in Chrome, so out it went. Using IE10 as only browser now. The machine is appreciably faster too. I have a copy of hijhack downloaded but will rake your link as its probably more up to date
 

My Computer

System One

  • OS
    Win 10
    Computer type
    PC/Desktop
    System Manufacturer/Model
    pc specialist made to order
    CPU
    Intel® Core™i7 Quad Core Processor i7-4790 (3.6GHz) 8MB Cache
    Motherboard
    ASUS® H81M-PLUS: Micro-ATX, LG1150, USB 3.0, SATA 6GBs
    Memory
    16GB KINGSTON DUAL-DDR3 1600MHz (2 x 8GB)
    Graphics Card(s)
    2GB NVIDIA GEFORCE GTX 750 Ti - DVI, mHDMI, VGA - 3D Vision Ready
    Sound Card
    ONBOARD 6 CHANNEL (5.1) HIGH DEF AUDIO (AS STANDARD)
    Monitor(s) Displays
    iiyama 24 inch flat screen
    Screen Resolution
    1920 x 1080
    Hard Drives
    1TB 3.5" SEAGATE SSHD, SATA 6Gb/s 7200 RPM (64MB + 8GB SSD CACHE)

    2TB Seagate SATA HDD

    500Gb SATA docked
    Case
    In Win Turbo
    Cooling
    Super Quiet 22dBA Triple Copper Heatpipe Intel CPU Cooler
    Keyboard
    microsoft mutlimedia keyboard
    Mouse
    logitech corded
    Internet Speed
    152mb
    Browser
    FF, IE11
    Antivirus
    AVG Internet Security 2015
    Other Info
    16x BLU-RAY WRITER DRIVE, 16x DVD ±R/±RW

    10/100/1000 GIGABIT LAN PORT
hijack this log

In what section would I look for this in regedit, been thought it but not successfully
 

Attachments

  • hijackthis.doc
    8.9 KB · Views: 141

My Computer

System One

  • OS
    Win 10
    Computer type
    PC/Desktop
    System Manufacturer/Model
    pc specialist made to order
    CPU
    Intel® Core™i7 Quad Core Processor i7-4790 (3.6GHz) 8MB Cache
    Motherboard
    ASUS® H81M-PLUS: Micro-ATX, LG1150, USB 3.0, SATA 6GBs
    Memory
    16GB KINGSTON DUAL-DDR3 1600MHz (2 x 8GB)
    Graphics Card(s)
    2GB NVIDIA GEFORCE GTX 750 Ti - DVI, mHDMI, VGA - 3D Vision Ready
    Sound Card
    ONBOARD 6 CHANNEL (5.1) HIGH DEF AUDIO (AS STANDARD)
    Monitor(s) Displays
    iiyama 24 inch flat screen
    Screen Resolution
    1920 x 1080
    Hard Drives
    1TB 3.5" SEAGATE SSHD, SATA 6Gb/s 7200 RPM (64MB + 8GB SSD CACHE)

    2TB Seagate SATA HDD

    500Gb SATA docked
    Case
    In Win Turbo
    Cooling
    Super Quiet 22dBA Triple Copper Heatpipe Intel CPU Cooler
    Keyboard
    microsoft mutlimedia keyboard
    Mouse
    logitech corded
    Internet Speed
    152mb
    Browser
    FF, IE11
    Antivirus
    AVG Internet Security 2015
    Other Info
    16x BLU-RAY WRITER DRIVE, 16x DVD ±R/±RW

    10/100/1000 GIGABIT LAN PORT
OK having a look now...



O2 - BHO: WebCake Layers - {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} - C:\Program Files\Web Cake\WebCakeIEClient.dll

Get rid of that.

If you have "Yontoo Layers" installed? Delete it immediately, uninstall it then delete any leftover folders. But get rid of that Webcake thing, I think it is your problem

There are a bunch of questionable things in there, but that one is probably the main culprit.

In Hijack This, select that, then hit "Fix". Then delete the program files. You may have to reboot.
 

My Computer

System One

  • OS
    Windows 8 Pro with Media Center/Windows 7
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Asus M2N-MX SE Plus § DualCore AMD Athlon 64 X2, 2300 MHz (11.5 x 200) 4400+ § Corsair Value Select
    CPU
    AMD 4400+/4200+
    Motherboard
    Asus M2N-MX SE Plus/Asus A8M2N-LA (NodusM)
    Memory
    2 GB/3GB
    Graphics Card(s)
    GeForce 8400 GS/GeForce 210
    Sound Card
    nVIDIA GT218 - High Definition Audio Controller
    Monitor(s) Displays
    Hitachi 40" LCD HDTV
    Screen Resolution
    "1842 x 1036"
    Hard Drives
    WDC WD50 00AAKS-007AA SCSI Disk Device
    ST1000DL 002-9TT153 SCSI Disk Device
    WDC WD3200AAJB-00J3A0 ATA Device
    WDC WD32 WD-WCAPZ2942630 USB Device
    WD My Book 1140 USB Device
    PSU
    Works 550w
    Case
    MSI "M-Box"
    Cooling
    Water Cooled
    Keyboard
    Dell Keyboard
    Mouse
    Microsoft Intellimouse
    Internet Speed
    Cable Medium Speed
    Browser
    Chrome/IE 10
    Antivirus
    Eset NOD32 6.x/Win Defend
    Other Info
    Recently lost my Windows 8 on my main PC, had to go back to Windows 7.
on my way
 

My Computer

System One

  • OS
    Win 10
    Computer type
    PC/Desktop
    System Manufacturer/Model
    pc specialist made to order
    CPU
    Intel® Core™i7 Quad Core Processor i7-4790 (3.6GHz) 8MB Cache
    Motherboard
    ASUS® H81M-PLUS: Micro-ATX, LG1150, USB 3.0, SATA 6GBs
    Memory
    16GB KINGSTON DUAL-DDR3 1600MHz (2 x 8GB)
    Graphics Card(s)
    2GB NVIDIA GEFORCE GTX 750 Ti - DVI, mHDMI, VGA - 3D Vision Ready
    Sound Card
    ONBOARD 6 CHANNEL (5.1) HIGH DEF AUDIO (AS STANDARD)
    Monitor(s) Displays
    iiyama 24 inch flat screen
    Screen Resolution
    1920 x 1080
    Hard Drives
    1TB 3.5" SEAGATE SSHD, SATA 6Gb/s 7200 RPM (64MB + 8GB SSD CACHE)

    2TB Seagate SATA HDD

    500Gb SATA docked
    Case
    In Win Turbo
    Cooling
    Super Quiet 22dBA Triple Copper Heatpipe Intel CPU Cooler
    Keyboard
    microsoft mutlimedia keyboard
    Mouse
    logitech corded
    Internet Speed
    152mb
    Browser
    FF, IE11
    Antivirus
    AVG Internet Security 2015
    Other Info
    16x BLU-RAY WRITER DRIVE, 16x DVD ±R/±RW

    10/100/1000 GIGABIT LAN PORT
There are a few other things in there, I'll keep looking.

O23 - Service: WebCacheService - Data Dynamics - C:\PROGRA~1\COMMON~1\Data Dynamics\ActiveReports Pro\WebCacheService.exe
O23 - Service: XoftSpyService - ParetoLogic Inc. - C:\Program Files\Common Files\XoftSpySE\6\xoftspyservice.exe

the first one, not sure what it is, but the second on, I've seen some MASSIVE complaints about that on the net. And any "Paretologic" programs.

This guy cites links from Prevx and others as to the nature of Xsoftspy. It's another virus.

Any opinion on XoftSpy SE? - Yahoo! Answers
 

My Computer

System One

  • OS
    Windows 8 Pro with Media Center/Windows 7
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Asus M2N-MX SE Plus § DualCore AMD Athlon 64 X2, 2300 MHz (11.5 x 200) 4400+ § Corsair Value Select
    CPU
    AMD 4400+/4200+
    Motherboard
    Asus M2N-MX SE Plus/Asus A8M2N-LA (NodusM)
    Memory
    2 GB/3GB
    Graphics Card(s)
    GeForce 8400 GS/GeForce 210
    Sound Card
    nVIDIA GT218 - High Definition Audio Controller
    Monitor(s) Displays
    Hitachi 40" LCD HDTV
    Screen Resolution
    "1842 x 1036"
    Hard Drives
    WDC WD50 00AAKS-007AA SCSI Disk Device
    ST1000DL 002-9TT153 SCSI Disk Device
    WDC WD3200AAJB-00J3A0 ATA Device
    WDC WD32 WD-WCAPZ2942630 USB Device
    WD My Book 1140 USB Device
    PSU
    Works 550w
    Case
    MSI "M-Box"
    Cooling
    Water Cooled
    Keyboard
    Dell Keyboard
    Mouse
    Microsoft Intellimouse
    Internet Speed
    Cable Medium Speed
    Browser
    Chrome/IE 10
    Antivirus
    Eset NOD32 6.x/Win Defend
    Other Info
    Recently lost my Windows 8 on my main PC, had to go back to Windows 7.
xsoft was something I tried and failed with today - prog deleted. The windows comes up with you are not allowed to make changes and refuses to let hijack this delete the line. I am admin by the way

it says go here: sys32/drivers/etc/hosts and delete line but this is all that shows

102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
 

My Computer

System One

  • OS
    Win 10
    Computer type
    PC/Desktop
    System Manufacturer/Model
    pc specialist made to order
    CPU
    Intel® Core™i7 Quad Core Processor i7-4790 (3.6GHz) 8MB Cache
    Motherboard
    ASUS® H81M-PLUS: Micro-ATX, LG1150, USB 3.0, SATA 6GBs
    Memory
    16GB KINGSTON DUAL-DDR3 1600MHz (2 x 8GB)
    Graphics Card(s)
    2GB NVIDIA GEFORCE GTX 750 Ti - DVI, mHDMI, VGA - 3D Vision Ready
    Sound Card
    ONBOARD 6 CHANNEL (5.1) HIGH DEF AUDIO (AS STANDARD)
    Monitor(s) Displays
    iiyama 24 inch flat screen
    Screen Resolution
    1920 x 1080
    Hard Drives
    1TB 3.5" SEAGATE SSHD, SATA 6Gb/s 7200 RPM (64MB + 8GB SSD CACHE)

    2TB Seagate SATA HDD

    500Gb SATA docked
    Case
    In Win Turbo
    Cooling
    Super Quiet 22dBA Triple Copper Heatpipe Intel CPU Cooler
    Keyboard
    microsoft mutlimedia keyboard
    Mouse
    logitech corded
    Internet Speed
    152mb
    Browser
    FF, IE11
    Antivirus
    AVG Internet Security 2015
    Other Info
    16x BLU-RAY WRITER DRIVE, 16x DVD ±R/±RW

    10/100/1000 GIGABIT LAN PORT
Then use Unlocker to delete the actual program and then delete all entries to it in Regedit.
 

My Computer

System One

  • OS
    Windows 8 Pro with Media Center/Windows 7
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Asus M2N-MX SE Plus § DualCore AMD Athlon 64 X2, 2300 MHz (11.5 x 200) 4400+ § Corsair Value Select
    CPU
    AMD 4400+/4200+
    Motherboard
    Asus M2N-MX SE Plus/Asus A8M2N-LA (NodusM)
    Memory
    2 GB/3GB
    Graphics Card(s)
    GeForce 8400 GS/GeForce 210
    Sound Card
    nVIDIA GT218 - High Definition Audio Controller
    Monitor(s) Displays
    Hitachi 40" LCD HDTV
    Screen Resolution
    "1842 x 1036"
    Hard Drives
    WDC WD50 00AAKS-007AA SCSI Disk Device
    ST1000DL 002-9TT153 SCSI Disk Device
    WDC WD3200AAJB-00J3A0 ATA Device
    WDC WD32 WD-WCAPZ2942630 USB Device
    WD My Book 1140 USB Device
    PSU
    Works 550w
    Case
    MSI "M-Box"
    Cooling
    Water Cooled
    Keyboard
    Dell Keyboard
    Mouse
    Microsoft Intellimouse
    Internet Speed
    Cable Medium Speed
    Browser
    Chrome/IE 10
    Antivirus
    Eset NOD32 6.x/Win Defend
    Other Info
    Recently lost my Windows 8 on my main PC, had to go back to Windows 7.
Maybe you can get rid of Xfostspy using Hijackthis in safe mode...
 

My Computer

System One

  • OS
    Windows 8 Pro with Media Center/Windows 7
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Asus M2N-MX SE Plus § DualCore AMD Athlon 64 X2, 2300 MHz (11.5 x 200) 4400+ § Corsair Value Select
    CPU
    AMD 4400+/4200+
    Motherboard
    Asus M2N-MX SE Plus/Asus A8M2N-LA (NodusM)
    Memory
    2 GB/3GB
    Graphics Card(s)
    GeForce 8400 GS/GeForce 210
    Sound Card
    nVIDIA GT218 - High Definition Audio Controller
    Monitor(s) Displays
    Hitachi 40" LCD HDTV
    Screen Resolution
    "1842 x 1036"
    Hard Drives
    WDC WD50 00AAKS-007AA SCSI Disk Device
    ST1000DL 002-9TT153 SCSI Disk Device
    WDC WD3200AAJB-00J3A0 ATA Device
    WDC WD32 WD-WCAPZ2942630 USB Device
    WD My Book 1140 USB Device
    PSU
    Works 550w
    Case
    MSI "M-Box"
    Cooling
    Water Cooled
    Keyboard
    Dell Keyboard
    Mouse
    Microsoft Intellimouse
    Internet Speed
    Cable Medium Speed
    Browser
    Chrome/IE 10
    Antivirus
    Eset NOD32 6.x/Win Defend
    Other Info
    Recently lost my Windows 8 on my main PC, had to go back to Windows 7.
OK they gone. what I did was instead of just ticking one, I ticked all three together and, apparently, they have gone!!! Oh please yes!!

just done hijack this again, the lines are still there, after reboot

If these are lines in registry, can I do a manual deletion? If so where?

I had not deleted Xoft but have now
 

My Computer

System One

  • OS
    Win 10
    Computer type
    PC/Desktop
    System Manufacturer/Model
    pc specialist made to order
    CPU
    Intel® Core™i7 Quad Core Processor i7-4790 (3.6GHz) 8MB Cache
    Motherboard
    ASUS® H81M-PLUS: Micro-ATX, LG1150, USB 3.0, SATA 6GBs
    Memory
    16GB KINGSTON DUAL-DDR3 1600MHz (2 x 8GB)
    Graphics Card(s)
    2GB NVIDIA GEFORCE GTX 750 Ti - DVI, mHDMI, VGA - 3D Vision Ready
    Sound Card
    ONBOARD 6 CHANNEL (5.1) HIGH DEF AUDIO (AS STANDARD)
    Monitor(s) Displays
    iiyama 24 inch flat screen
    Screen Resolution
    1920 x 1080
    Hard Drives
    1TB 3.5" SEAGATE SSHD, SATA 6Gb/s 7200 RPM (64MB + 8GB SSD CACHE)

    2TB Seagate SATA HDD

    500Gb SATA docked
    Case
    In Win Turbo
    Cooling
    Super Quiet 22dBA Triple Copper Heatpipe Intel CPU Cooler
    Keyboard
    microsoft mutlimedia keyboard
    Mouse
    logitech corded
    Internet Speed
    152mb
    Browser
    FF, IE11
    Antivirus
    AVG Internet Security 2015
    Other Info
    16x BLU-RAY WRITER DRIVE, 16x DVD ±R/±RW

    10/100/1000 GIGABIT LAN PORT
OK you also have Snapdo - It is a continuous feed of junk:

Delete these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=TightropeYB&dpid=TightropeYB&co=GB&userid=2b4d0d3e-d700-4966-b912-f8dbe818cd22&searchtype=ds&q={searchTerms}&installDate=22/03/2013
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = Search

And these

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/?publisher=TightropeYB&dpid=TightropeYB&co=GB&userid=2b4d0d3e-d700-4966-b912-f8dbe818cd22&searchtype=ds&q={searchTerms}&installDate=22/03/2013
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/?publisher=TightropeYB&dpid=TightropeYB&co=GB&userid=2b4d0d3e-d700-4966-b912-f8dbe818cd22&searchtype=ds&q={searchTerms}&installDate=22/03/2013

Does Snapdo come up as a search engine? It Ain't a search, it's a virus!

How to Remove Search.Snap.do Virus from IE/FF/Chrome? (Snap.do Toolbar Removal Guide) | Anvisoft - Labs

(Solved) How to Remove Snap.do Search from Chrome, Mozilla , IE
 

My Computer

System One

  • OS
    Windows 8 Pro with Media Center/Windows 7
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Asus M2N-MX SE Plus § DualCore AMD Athlon 64 X2, 2300 MHz (11.5 x 200) 4400+ § Corsair Value Select
    CPU
    AMD 4400+/4200+
    Motherboard
    Asus M2N-MX SE Plus/Asus A8M2N-LA (NodusM)
    Memory
    2 GB/3GB
    Graphics Card(s)
    GeForce 8400 GS/GeForce 210
    Sound Card
    nVIDIA GT218 - High Definition Audio Controller
    Monitor(s) Displays
    Hitachi 40" LCD HDTV
    Screen Resolution
    "1842 x 1036"
    Hard Drives
    WDC WD50 00AAKS-007AA SCSI Disk Device
    ST1000DL 002-9TT153 SCSI Disk Device
    WDC WD3200AAJB-00J3A0 ATA Device
    WDC WD32 WD-WCAPZ2942630 USB Device
    WD My Book 1140 USB Device
    PSU
    Works 550w
    Case
    MSI "M-Box"
    Cooling
    Water Cooled
    Keyboard
    Dell Keyboard
    Mouse
    Microsoft Intellimouse
    Internet Speed
    Cable Medium Speed
    Browser
    Chrome/IE 10
    Antivirus
    Eset NOD32 6.x/Win Defend
    Other Info
    Recently lost my Windows 8 on my main PC, had to go back to Windows 7.
no snap do found, web cake folder deleted, no yontoo found. I know where most have come from my daughter is forever downloading, I keep telling her to untick boxes!! AGH!

Hijack this keeps telling me system wont let me delete these!!! And points me to here:

# Copyright (c) 1993-2009 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
# 127.0.0.1 localhost
# ::1 localhost
 

My Computer

System One

  • OS
    Win 10
    Computer type
    PC/Desktop
    System Manufacturer/Model
    pc specialist made to order
    CPU
    Intel® Core™i7 Quad Core Processor i7-4790 (3.6GHz) 8MB Cache
    Motherboard
    ASUS® H81M-PLUS: Micro-ATX, LG1150, USB 3.0, SATA 6GBs
    Memory
    16GB KINGSTON DUAL-DDR3 1600MHz (2 x 8GB)
    Graphics Card(s)
    2GB NVIDIA GEFORCE GTX 750 Ti - DVI, mHDMI, VGA - 3D Vision Ready
    Sound Card
    ONBOARD 6 CHANNEL (5.1) HIGH DEF AUDIO (AS STANDARD)
    Monitor(s) Displays
    iiyama 24 inch flat screen
    Screen Resolution
    1920 x 1080
    Hard Drives
    1TB 3.5" SEAGATE SSHD, SATA 6Gb/s 7200 RPM (64MB + 8GB SSD CACHE)

    2TB Seagate SATA HDD

    500Gb SATA docked
    Case
    In Win Turbo
    Cooling
    Super Quiet 22dBA Triple Copper Heatpipe Intel CPU Cooler
    Keyboard
    microsoft mutlimedia keyboard
    Mouse
    logitech corded
    Internet Speed
    152mb
    Browser
    FF, IE11
    Antivirus
    AVG Internet Security 2015
    Other Info
    16x BLU-RAY WRITER DRIVE, 16x DVD ±R/±RW

    10/100/1000 GIGABIT LAN PORT
It's your HOSTS file and there is nothing in there at all, if in fact that is your hosts file.

I don't care what it said somewhere else, those entries were in your PC, HijackThis showed them. It's an infection, not a Program. So parts of it cannot be uninstalled, just have to remove the pieces of it.

So, the popups have stopped? If they have mark this as Solved. At any rate my original assessment has been proved, you had a virus. Might still have parts of it, some viruses are so bad that there is nothing to do but Format C:

But if you do that, I would suggest securing the drive, use a Zero-Write program to write 0's on the whole drive.
 

My Computer

System One

  • OS
    Windows 8 Pro with Media Center/Windows 7
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Asus M2N-MX SE Plus § DualCore AMD Athlon 64 X2, 2300 MHz (11.5 x 200) 4400+ § Corsair Value Select
    CPU
    AMD 4400+/4200+
    Motherboard
    Asus M2N-MX SE Plus/Asus A8M2N-LA (NodusM)
    Memory
    2 GB/3GB
    Graphics Card(s)
    GeForce 8400 GS/GeForce 210
    Sound Card
    nVIDIA GT218 - High Definition Audio Controller
    Monitor(s) Displays
    Hitachi 40" LCD HDTV
    Screen Resolution
    "1842 x 1036"
    Hard Drives
    WDC WD50 00AAKS-007AA SCSI Disk Device
    ST1000DL 002-9TT153 SCSI Disk Device
    WDC WD3200AAJB-00J3A0 ATA Device
    WDC WD32 WD-WCAPZ2942630 USB Device
    WD My Book 1140 USB Device
    PSU
    Works 550w
    Case
    MSI "M-Box"
    Cooling
    Water Cooled
    Keyboard
    Dell Keyboard
    Mouse
    Microsoft Intellimouse
    Internet Speed
    Cable Medium Speed
    Browser
    Chrome/IE 10
    Antivirus
    Eset NOD32 6.x/Win Defend
    Other Info
    Recently lost my Windows 8 on my main PC, had to go back to Windows 7.
I am more than grateful for your help, you have been brilliant. I shall wait now and see how things pan out. At least I know where to look if reqd. Thanks again.
 

My Computer

System One

  • OS
    Win 10
    Computer type
    PC/Desktop
    System Manufacturer/Model
    pc specialist made to order
    CPU
    Intel® Core™i7 Quad Core Processor i7-4790 (3.6GHz) 8MB Cache
    Motherboard
    ASUS® H81M-PLUS: Micro-ATX, LG1150, USB 3.0, SATA 6GBs
    Memory
    16GB KINGSTON DUAL-DDR3 1600MHz (2 x 8GB)
    Graphics Card(s)
    2GB NVIDIA GEFORCE GTX 750 Ti - DVI, mHDMI, VGA - 3D Vision Ready
    Sound Card
    ONBOARD 6 CHANNEL (5.1) HIGH DEF AUDIO (AS STANDARD)
    Monitor(s) Displays
    iiyama 24 inch flat screen
    Screen Resolution
    1920 x 1080
    Hard Drives
    1TB 3.5" SEAGATE SSHD, SATA 6Gb/s 7200 RPM (64MB + 8GB SSD CACHE)

    2TB Seagate SATA HDD

    500Gb SATA docked
    Case
    In Win Turbo
    Cooling
    Super Quiet 22dBA Triple Copper Heatpipe Intel CPU Cooler
    Keyboard
    microsoft mutlimedia keyboard
    Mouse
    logitech corded
    Internet Speed
    152mb
    Browser
    FF, IE11
    Antivirus
    AVG Internet Security 2015
    Other Info
    16x BLU-RAY WRITER DRIVE, 16x DVD ±R/±RW

    10/100/1000 GIGABIT LAN PORT
Sorry #david, adaware installed stuff I did not want, changed my search engine and installed toolbars without my knowledge or acceptance. It also failed to find premiumoptions

You need to pay attention when installing something.
If you would have read the prompts as you installed it none of that would have happened.

***************************************************************************

EDIT-- I say it is a good program because it keeps adware & spyware out.
It tells me when it finds something & gives me the option of what to do with it.
I don't just say it is good.
I know it is good from the results I get from it.

This edit isn't pointed at you elbmek. :)
Just anyone who says it is a bad program without giving reasons why they say it is a bad program.

***************************************************************************

Getting unwanted stuff installed by not reading the install prompts is easy to have happen.
I've done it myself.
I learned to go slowly when installing anything.
I suggested AdAware because I thought your problem was adware related.
Sorry it didn't help.
I hope you find a solution soon. :)
 

My Computer

System One

  • OS
    Windows 8.1.1 Pro with Media Center
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Gateway
    CPU
    AMD K140 Cores 2 Threads 2 Name AMD K140 Package Socket FT1 BGA Technology 40nm
    Motherboard
    Manufacturer Gateway Model SX2110G (P0)
    Memory
    Type DDR3 Size 8192 MBytes DRAM Frequency 532.3 MHz
    Graphics Card(s)
    ATI AMD Radeon HD 7310 Graphics
    Sound Card
    AMD High Definition Audio Device Realtek High Definition Audio USB Audio Device
    Monitor(s) Displays
    Name 1950W on AMD Radeon HD 7310 Graphics Current Resolution 1366x768 pixels Work Resolution 1366x76
    Screen Resolution
    Current Resolution 1366x768 pixels Work Resolution 1366x768 pixels
    Hard Drives
    AMD K140
    Cores 2
    Threads 2
    Name AMD K140
    Package Socket FT1 BGA
    Technology 40nm
    Specification AMD E1-1200 APU with Radeon HD Graphics
    Family F
    Extended Family 14
    Model 2
    Extended Model 2
    Stepping 0
    Revision ON-C0
    Instruction
    Browser
    Opera 24.0
    Antivirus
    Avast Internet Security
The people who make these things try to make them look like the system generated it.

One way to possibly protect yourself is to "Personalise" your Windows GUI (e.g. change the Font Type, Font Style or the Colour Scheme).
This only works against poorly written malware.

Years ago I saw one of those fake XP alerts.
I knew it was a fake message as it used the default blue colour scheme (I was using the XP silver scheme).

Yeah, saw those too...
They always pick the most used theme globally (as they can detect which browser you use, what system, they can also detect which color scheme is used).
That's why I always use some light modified theme and not the mainstream one. AeroLite for instance.

There are of course some users that amaze me as well: very sophisticated highly modified, custom themes but you don't see this everywhere of course.

Ads using Aerolite Scheme? Don't see those yet because AeroLite looks uglier than Aero to most. So if 2 guys from the whole bunch of Win8 users use a specific theme and all the rest use the default one, then you've guessed how ads/popup windows will look next.
 

My Computer

System One

  • OS
    Windows 10 x64
    Computer type
    Laptop
    System Manufacturer/Model
    HP Envy DV6 7250
    CPU
    Intel i7-3630QM
    Motherboard
    HP, Intel HM77 Express Chipset
    Memory
    16GB
    Graphics Card(s)
    Intel HD4000 + Nvidia Geforce 630M
    Sound Card
    IDT HD Audio
    Monitor(s) Displays
    15.6' built-in + Samsung S22D300 + 17.3' LG Phillips
    Screen Resolution
    multiple resolutions
    Hard Drives
    Samsung SSD 250GB + Hitachi HDD 750GB
    PSU
    120W adapter
    Case
    small
    Cooling
    laptop cooling pad
    Keyboard
    Backlit built-in + big one in USB
    Mouse
    SteelSeries Sensei
    Internet Speed
    slow and steady
    Browser
    Chromium, Pale Moon, Firefox Developer Edition
    Antivirus
    Windows Defender
    Other Info
    That's basically it.
2 program i use and recommend for malware removal are Malwarebytes ans SuperAntiSpyware, and i run both on computers regular customers of mine to remove malware with good results ,some are nastier than others and may require a bit more work ..
 

My Computer

System One

  • OS
    win8.1.1 enterprise
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Hinze57
    CPU
    AMD FX 6100 6core 3.30gHz
    Motherboard
    gigibyte ga-78lmy-s2p
    Memory
    4gig ddr3
    Graphics Card(s)
    Radon hd5000 Series
    Sound Card
    onboard realtek hd
    Monitor(s) Displays
    19" viewsonic/ 22"Samsung
    Screen Resolution
    1680x1050
    Hard Drives
    128gig ssd Kingston
    80gig WD 10000 rpm spinner
    Case
    micro
    Keyboard
    microsoft curve 200
    Mouse
    Logitech wireless M215
    Internet Speed
    high speed 20
    Browser
    ie 11
    Antivirus
    windows defender
    Other Info
    updated enterprise apr 2/14
Well, David, if AdAware works for you, then use it- It's simply too difficult to install Just Ad Aware all by itself without the utter CACK that's tacked onto it which cannot be avoided without extreme difficulty. It must be difficult to see the prompts for the extra stuff. I know with me, I look at every aspect of every installer with intense scrutiny, so I would have been able to avoid installing the malware that comes with adaware.

But most people who simply download programs and install them, really don't know where to look to find out how to avoid this. Actually most people do not understand they are being forced to install programs they never wanted. There are two programs that are on my permanent Shi-ite list: IMGburn and Ad-Aware. Both of them deliberately hide the malware installers so they are very difficult to avoid installing.

Distributors of software that do this need to be run off the face of the earth, I don't care HOW "good" the software is. I use an old version of IMGburn which does not have the forced malware installations, and I've never updated it since they started practicing this kind of invasion. ElbMek's Problem is based on this practice, and Ad-Aware participates in it, which makes them propagators of the problem rather than part of the solution.

If you have Malwarebytes, I would nto bother with "SuperAntiApyware" - it's a borderline program, and it should not be installed as to run in "Resident" mode, because it causes a bunch of problems. But it's fine for single-use scanning.
 

My Computer

System One

  • OS
    Windows 8 Pro with Media Center/Windows 7
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Asus M2N-MX SE Plus § DualCore AMD Athlon 64 X2, 2300 MHz (11.5 x 200) 4400+ § Corsair Value Select
    CPU
    AMD 4400+/4200+
    Motherboard
    Asus M2N-MX SE Plus/Asus A8M2N-LA (NodusM)
    Memory
    2 GB/3GB
    Graphics Card(s)
    GeForce 8400 GS/GeForce 210
    Sound Card
    nVIDIA GT218 - High Definition Audio Controller
    Monitor(s) Displays
    Hitachi 40" LCD HDTV
    Screen Resolution
    "1842 x 1036"
    Hard Drives
    WDC WD50 00AAKS-007AA SCSI Disk Device
    ST1000DL 002-9TT153 SCSI Disk Device
    WDC WD3200AAJB-00J3A0 ATA Device
    WDC WD32 WD-WCAPZ2942630 USB Device
    WD My Book 1140 USB Device
    PSU
    Works 550w
    Case
    MSI "M-Box"
    Cooling
    Water Cooled
    Keyboard
    Dell Keyboard
    Mouse
    Microsoft Intellimouse
    Internet Speed
    Cable Medium Speed
    Browser
    Chrome/IE 10
    Antivirus
    Eset NOD32 6.x/Win Defend
    Other Info
    Recently lost my Windows 8 on my main PC, had to go back to Windows 7.
Back
Top